NextDNS
For DNS I find Next DNS to be best. NextDNS is a service that significantly enhances your online security and privacy. Acting as an advanced guard for your network, it offers features like ad blocking, tracker blocking, and malware protection to safeguard your browsing experience.
Account Setup
By creating an account, you can block top domains known for malicious activity, adding an extra layer of protection. You can also disable native trackers, making it an excellent choice, especially for Windows users.
NextDNS account.
Before we start go ahead and make an account. Otherwise proceed to the add DNS section if you do not want an account.
Security Settings
- When you are logged in, click on the “Security” tab at the top.
- Enable “Threat Intelligence Feeds.”
- Disable “AI-Driven Threat Detection” since it’s a beta.
- Disable “Google Safe Browsing.”
- Enable “Cryptojacking Protection” if you use crypto.
- Enable “DNS Rebinding Protection.”
- Enable “IDN Homograph Attacks Protection.”
- Enable “Typesquatting Protection.”
- Enable “Domain Generation Algorithms (DGAs) Protection.”
- Enable “Block Newly Registered Domains (NRDs).”
- Enable “Block Dynamic DNS Hostnames.”
- Enable “Block Parked Domains.”
- Under “Block Top-Level Domains (TLDs),” click on the “ADD A TLD” option.
- Add all the “Spamhaus Most Abused TLDs.”
- Add any domains you wouldn’t want to visit.
- I personally disabled all TLDs that are not written in Latin; this is a preference. If you are in Saudi Arabia, disabling Arabic domains may not be advisable.
DNS And Privacy Settings
Now if you go to the “Privacy” category, we can start blocking DNS queries:
- Click on the “ADD A BLOCKLIST” option.
- Click on the search bar and write “hagezi.”
- Click on the “ADD” button next to “HaGeZi – Multi Ultimate.”
- Click on the search bar and write “xtra.”
- Click on the “ADD” button next to “1Hosts (Xtra).”
- I personally also add “No Google” and “No Facebook” (this is optional).
- Scroll down to “Native Tracking Protection.”
- Click on the “ADD” button.
- I personally enable all options and have no issues on any machine.
- Click on the cross and scroll down to the bottom.
- Enable “Block Disguised Third-Party Trackers.”
- Disable “Allow Affiliate & Tracking Links.”
This setup blocks most unwanted elements. However, consider that guests may not want to use your Wi-Fi if you block something they use. If this is a concern, avoid extensive blocking on your router. I only apply comprehensive blocking of apps on my devices, not on the network itself.
DNS And Parental Control Settings
- Go to “Parental Control.”
- Scroll down and click on the “ADD A WEBSITE, APP OR GAME.”
- Add any game or website you don’t want to use.
- Click on the cross.
- Scroll further down to find the “Categories” section.
- Click on the “ADD A CATEGORY” button.
- Add any unwanted categories and click on the cross.
- Scroll to the bottom.
- Disable “SafeSearch.”
- Disable “YouTube Restricted Mode.”
- Enable “Block Bypass Methods.”
Final Settings
- Go to the “Settings” tab.
- Disable “Enable Logs.”
- Click on the “Clear logs” option.
- Scroll down and click on the “Bypass Age Verification” option.
Now you are done setting up a more extreme version of NextDNS. It’s important to note that using all these settings may lead to some sites not working. If you encounter a website that doesn’t work, here is the solution:
- Go to “Allowlist.”
- Add a domain (nullvoided.com) without https://.
A domain consists of a name, dot, and something (example.com), without https:// or www. (or anything else that might come before the initial name of the page).